Home > Information Security News > Information security skills must include communication, says Dorey
Information Security News:
EMAIL THIS

Information security skills must include communication, says Dorey

By Ron Condon, U.K. Bureau Chief
29 Apr 2009 | SearchSecurity.co.uk

Enterprise IT news roundup
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

LONDON -- A successful information security professional needs to acquire a wide range of new skills in order to command the right level of influence, according to one of the industry's most experienced veterans.

Paul Dorey, the keynote speaker on the second day of the Infosecurity Europe conference, has held senior security roles in banks and most recently at the global oil company BP Plc., and is now chairman of the Institute of Information Security Professionals.

For more Infosecurity Europe 2009 news

Get the latest news and interviews from the conference floor. Check out our live coverage of Infosecurity Europe 2009.
At the Infosecurity event, hosted in London, Dorey explained why security professionals will need to adapt their manner and language in order to deal with different groups of people in their organisations.

"We are entering a time when IT security people are going to have to move from being merely advisors to the business to real professionals whose views are listened to," he said. As IT supports every aspect of life, security breaches become potentially life-threatening or disastrous for their organisations. Just as bridge designers and structural engineers work to common and consistent standards and are therefore respected, he said, so security professionals should command the same level of respect.

For that to happen, security professionals need to communicate effectively with a wide range of disciplines – including audit, risk assessment and compliance, IT and engineering. "They need to be like chameleons to fit into those disciplines," he said. "You may not become an expert in them all, but you must at least don the facade. ... Get some mentoring to help you understand them."

Don't miss need-to-know info!
Security pros can't afford to be the last to know. Sign up for email updates from SearchSecurity.co.uk and you'll never be behind the curve!
Dorey predicted that many new threats will come in the physical infrastructure that increasingly depends on microcontrollers, or computer systems-on-a-chip, which are still largely ignored by the security world. The integrity of those physical assets will become increasingly important, hence the need for a greater appreciation of engineering.

Most of all, he urged security people to be business-like in their approach. This means thinking of the business context and relevance of whatever they propose; setting realistic priorities; working to influence people; managing change; being convincing in the boardroom, and showing leadership.

"I'm pleased that security people are now going on MBA courses. We ought to send more people for that kind of training," he said.

And to be really effective, he added, security should make things happen rather than try to block them. "Their attitude should be, 'You tell me what you want to do, and I'll show you how,'" he said.

Tags: IT Security Jobs, Careers and Certification TrainingSecurity Policies and User AwarenessVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
IT Security Jobs, Careers and Certification Training
Information security salaries start to rise, recruitment rebounds
Upsurge in infosec jobs for 2010
Salary research shows upturn for those who know how to sell security
M86 buys Web security gateway vendor Finjan
How to prepare for an information security job interview
Some IT security certifications are overvalued, analyst says
Information security salaries hit the buffers
Information security recruitment freezes as security staffs sit tight
Poll: Information security salaries remain steady despite recession
Social hacking: The easy way to breach network security

Security Policies and User Awareness
Cloud-based services require stalwart business continuity plans
Preventing phishing attacks: Enterprise best practices
CISOs take measured steps to reduce social media risks
Increasing information security awareness in the enterprise
How to develop a culture of security in the enterprise
Creating and enforcing a clear-desk policy
Physical security threats: Don't gift your data away
Cut down on calls to help desk with cybersecurity awareness training
Layoffs prompt insider threat fears, cybersecurity survey finds
How to write an information security policy

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
IISP (Institute of Information Security Professionals)  (SearchSecurityUK.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



IT Solutions for the UK: Data Security, Network Security, Application Security